The ECB told banks to build AI-enabled defence. It didn't say what that means.
The ECB's July letter asks 110 banks for an action plan by 31 October. Its annex spends paragraphs on patching, attack surface and governance, and one line on "AI-enabled defensive capabilities." That blank space will define the benchmark. Here's what we think belongs in it, and why it isn't alert triage.
Huntbase perspective · September 2026
On 7 July, Claudia Buch, chair of the ECB's Supervisory Board, wrote to the CEOs of all 110 significant institutions under the Single Supervisory Mechanism. The letter asks each bank to assess how frontier AI changes its cyber risk and to file an action plan with its Joint Supervisory Team by 31 October, complete with owners, budgets and dates. The ECB will then benchmark every plan against every other in a horizontal analysis and feed the results back into supervision.
It is the first Dear-CEO letter the SSM has sent about a technology threat. It arrived the same day as an ESRB warning on systemic cyber risk from frontier AI models. And it pushed the annual IT Risk Questionnaire back five months to give banks room to work on it. Supervisors do not clear the calendar for a topic they consider marginal.
We have spent the summer reading the letter, its annexes, the sources it cites, and the vendor responses that followed. Here is what we think most plans will get wrong.
Read the annex, not the headline
The letter names four short-term focus areas and two structural ones. Most coverage lists them and moves on. The more revealing document is Annex 1, where the ECB spells out what it wants under each.
Area 1 (attack surface) gets four bullets. Area 2 (vulnerability and patch management) gets three, including guidance on AI-based scanning, staffing and emergency change management. Area 4 (governance) gets three plus a paragraph on risk appetite. Area 5 (defence-in-depth) gets six.
Area 3 — "enhance monitoring, detection and AI-enabled defensive capabilities" — gets one. It says to strengthen monitoring of application logs, access logs and network traffic to catch indicators of compromise and attempted exploitation.
That is it. The one area with "AI-enabled" in its title is the one the ECB describes least. We do not read this as a lack of interest. The supervisor knows what a patch cycle looks like and can write prescriptive guidance about it. AI-enabled defence is newer, and the ECB has left it to banks to define. Whatever a bank writes under area 3 will become part of the benchmark the ECB uses on everyone else.
The market is answering the questions that are already answered
Look at who has published a response to the letter. Autonomous penetration-testing vendors mapped their platforms to attack surface and patch validation. Attack-surface-management and ratings vendors mapped to asset inventory and third-party risk. Identity vendors mapped to phishing-resistant MFA and privileged access. Supply-chain and SBOM specialists mapped to area 4. All of it is useful, and all of it lands in the areas where the annex is already detailed.
Almost nobody is writing seriously about area 3, and the reason is structural. The large "agentic SOC" market that emerged over the past two years is built around alert triage: an alert comes in, an agent investigates it, a verdict comes out. Every major platform now ships named triage agents. Gartner still places AI-driven SOC agents at the Technology Trigger stage with low single-digit penetration, and commentators keep flagging auditability of agent decisions as a blocker in regulated industries. Triage automation is real and valuable. But it starts from an alert, and an alert only fires on something a detection engineer already anticipated.
The letter's own logic points somewhere else
Two sentences in the annex matter more than the rest. The ECB writes that a prudent posture "assumes that perimeter defences will be breached", and that remediation planning should account for threats originating inside the network, not only outside it.
Put that next to the data the ECB cites. CERT-EU's April blog, listed first in the letter's references, reports Google M-Trends 2026 figures showing mean time-to-exploit has fallen from 63 days in 2018 to an estimated negative seven days now. Exploitation, on average, precedes the patch. CERT-EU's own recommendation for what defenders should do about detection is to invest in behavioural detection, anomaly monitoring and AI-assisted threat hunting, and to plan incident response for higher-speed, higher-volume scenarios.
Follow the chain. If exploitation happens before the patch exists, patch velocity cannot be the primary control for the exposure window. If the perimeter is assumed breached, the question that matters is not "did an alert fire?" but "is something already inside that produced no alert?" That question has a name. It is threat hunting, and it has been chronically under-resourced in banks because it runs on scarce senior analysts working one hypothesis at a time.
AI changes the economics of hunting the same way it changed the economics of vulnerability discovery. That is the substance of area 3, and it is what we think a credible plan should say.
What "AI-enabled defence" should mean in a plan
We build agentic hunting, so discount our view accordingly. But here is the test we would apply to any area 3 commitment, regardless of vendor.
It starts from a lead, not an alert. A new CVE on the KEV list, a supplier disclosure, a CERT advisory, an anomaly in identity logs, an entity that surfaced in last week's hunt. Intelligence-led hunting turns each of those into a question about your own estate and answers it.
It runs a pathway, not a query. One query answers one thing. A hunt is a sequence: query the SIEM, pivot to the endpoints that match, pull process trees from the EDR or an osquery fleet, check identity for the accounts involved, decide at each branch whether to widen or close. A useful AI-enabled capability plans and executes that whole pathway, across tools with different query languages, and stops for a human at the branches that carry real consequences.
It leaves a reusable artefact. The pathway that answered "did the Ivanti disclosure touch us?" should run again unchanged when the next edge-device zero-day lands. The ECB's area 6 asks banks to share defensive strategies and remediation approaches through trusted channels. A structured, portable playbook is exactly the kind of artefact that can be shared. A Slack thread and a notebook of half-finished queries are not.
It shows its work. The ECB conditions the use of AI-native defensive tools on governance, validation and human oversight. Every step needs to record what it queried, where, and what came back. A hunt with no provenance is not evidence a JST can use.
It produces numbers. Hunts run, findings confirmed that detection missed, time from disclosure to fleet-wide answer, share of hunting automated. Banks will need these for the risk tolerance framework the letter tells them to revisit, and for the quarterly conversations with the JST that follow submission.
Why this matters beyond the deadline
Frank Elderson said in June that smaller lenders may struggle to fund defences the largest banks can afford. He is right, and hunting is where the gap is widest. A global systemically important bank can staff a hunting team. A mid-sized universal bank cannot, and it faces the same negative-seven-day exploit window. Agentic hunting is one of the few capabilities where AI closes rather than widens that gap: the hypotheses, playbooks and decision trees a well-resourced team writes can run in an under-resourced one.
The ECB has also told banks what happens after 31 October. JSTs will engage on each plan and monitor delivery. The horizontal analysis will surface who is ahead and who is behind. The letter carries no fine because it does not need one; the consequence is supervisory findings and, for laggards, SREP pressure. Banks that submit a plan with a live hunting capability and a baseline number will set the bar. Banks that submit a paragraph about log monitoring will be measured against it.
What we would do this month
If you own the area 3 section of your bank's plan, three things fit inside the eight weeks left.
First, baseline. Count the hunts your team ran last quarter, how long the last "are we affected?" question took to answer across all telemetry, and how many findings came from hunting rather than alerts. Most teams do not have these numbers. Having them at all puts you ahead.
Second, connect a subset. You do not need every log source to start. A SIEM index, an EDR or osquery fleet, and an identity provider are enough to run intelligence-led hunts against the techniques that matter for your threat profile.
Third, write the commitment in the plan's own terms: owner, budget, dates, KPIs, and the governance under which the AI operates. Put the pilot's first results in the submission if you have them.
Huntbase builds agentic, intelligence-led threat hunting. Scout, its AI investigator, plans and runs hunting pathways across your SIEM, EDR, osquery fleet, cloud, identity and SaaS tools, pauses at checkpoints for your decision, and leaves every step documented. huntbase.io
Sources
- ECB Banking Supervision, letter SSM-2026-0301, "Addressing AI-enabled cybersecurity threats", 7 July 2026
- CERT-EU, "AI is changing the economics of vulnerability discovery. Defenders should adapt now", 21 April 2026
- Euronews, "ECB tells Europe's biggest banks to prepare for AI-powered cyber threats", 7 July 2026
- Reuters via Global Banking & Finance, Frank Elderson remarks, 3 June 2026
- A&O Shearman, "ECB requires significant institutions to address AI-enabled cybersecurity threats", 9 July 2026
- D3 Security, "The Best AI SOC Platforms 2026" (Gartner Hype Cycle reference), July 2026
- Prophet Security, "Top 5 AI SOC Analyst Platforms of 2026", August 2026